Spy Trojan

About “Trojan-Spy.Win32.Zbot.aygb” infection

Malware Removal

The Trojan-Spy.Win32.Zbot.aygb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.aygb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Zbot.aygb?


File Info:

name: E569461BEA00FA26D8ED.mlw
path: /opt/CAPEv2/storage/binaries/89ad446769a2a54da0b72d54b7abc72a4b9d857825528b60ff7ca7c11451e360
crc32: 7B3041D4
md5: e569461bea00fa26d8ed82200f2ad75a
sha1: ae3f4a81bbbdc17fb6af547d0716f1b593f4f697
sha256: 89ad446769a2a54da0b72d54b7abc72a4b9d857825528b60ff7ca7c11451e360
sha512: 95c3c7315507a2ed1ef8a1c8974df06ad0659b96f23c8523e03beb21a41d59db16d0dc17dcea834dd43e01e501803dde41cdb1c0aa462ddb903036d16b65b7d6
ssdeep: 3072:ISW7/ptU6Lh2JcDwt9P3rv3Zvu1vNxQjBSWZYKXlHX/feWt1bnmPcnR1qA9f:ODM6LhlDwj7vp4b+MWNHX/d9D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12824CF1B71D1D337C3F55B32BD465EABA37E7A4109F1520787801F156FB2AAE6A0B220
sha3_384: 69398f763116e63f8d269ff8d42dd73082d70bd497b63dda8b0fbd6c2456223859148b5da81f02ae2f1582980062cc61
ep_bytes: 558bec83c4dc6836590000684f36386c
timestamp: 2007-04-17 06:47:54

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.aygb also known as:

BkavW32.MosquitoQKB.Fam.Trojan
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.e569461bea00fa26
McAfeePWS-Zbot.gen.nn
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Kryptik.4116634a
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
VirITTrojan.Win32.Small.HQS
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.JSA
APEXMalicious
KasperskyTrojan-Spy.Win32.Zbot.aygb
BitDefenderMemScan:Trojan.Spy.ZBot.EQH
NANO-AntivirusTrojan.Win32.Zbot.cporw
SUPERAntiSpywareTrojan.Agent/Gen-DitherC
MicroWorld-eScanMemScan:Trojan.Spy.ZBot.EQH
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.114c0140
Ad-AwareMemScan:Trojan.Spy.ZBot.EQH
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.PWS.Panda.387
ZillyaTrojan.Zbot.Win32.34238
TrendMicroTROJ_SPYEYE.SMEP
SentinelOneStatic AI – Malicious PE
GDataMemScan:Trojan.Spy.ZBot.EQH
JiangminTrojanSpy.Zbot.auaa
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.196433
ArcabitTrojan.Spy.ZBot.EQH
ViRobotTrojan.Win32.A.Zbot.223744.A
MicrosoftPWS:Win32/Zbot.gen!Y
TACHYONTrojan-Spy/W32.ZBot.223744.T
AhnLab-V3Trojan/Win32.Zbot.R2835
Acronissuspicious
BitDefenderThetaAI:Packer.44F3F82E1F
ALYacMemScan:Trojan.Spy.ZBot.EQH
MAXmalware (ai score=99)
VBA32Trojan.Zeus.EA.0999
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojanSpy.Zbot!K0GoSLmzbWo
IkarusTrojan.Win32.Spyeye
MaxSecureTrojan.Malware.1613656.susgen
FortinetW32/Zbot.AYGB!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.bea00f
PandaTrj/Genetic.gen

How to remove Trojan-Spy.Win32.Zbot.aygb?

Trojan-Spy.Win32.Zbot.aygb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment